1. Candidate provider categories
| Category | Candidate / architecture | Purpose | Current truth |
|---|---|---|---|
| Authentication | Supabase | Verified user sessions and OAuth/magic link | Environment-dependent |
| API compute | Render or approved equivalent | Canonical FastAPI service | Production not verified |
| Edge | Cloudflare Workers/Pages | WAF, static delivery and fail-closed proxy | Bindings required |
| Evidence storage | Cloudflare R2 or approved equivalent | Encrypted documents | NOT_CONFIGURED locally |
| Database | Managed PostgreSQL | Canonical tenant data | Staging required |
| Malware | ClamAV deployment | Upload scanning | Quarantine when unavailable |
| Meta WhatsApp Business Platform | Official business messages/coexistence | NOT_CONFIGURED | |
| Payments | Approved payment provider | Payment and settlement evidence | NOT_CONFIGURED |
| AI | Confidential approved capability routes; active subprocessors disclosed when legally required | Capability-specific inference | Policy and credentials required |
| Observability | Approved redacted telemetry provider or self-hosted store | Error/security monitoring | Not selected |
2. Approval requirements
Before activation, Bodhi records provider legal entity, service, processing purpose, data classes, locations, subprocessors, retention/training, security terms, DPA, breach contact, deletion method and configuration evidence. AI providers additionally require capability evaluation and tenant data policy.
3. Changes
Material subprocessor changes will update this versioned disclosure and provide notice where required. Customers with a contractual objection process may use that process; otherwise incompatible providers must remain disabled.
4. Cross-border processing
No India-only claim is made without deployment evidence. Actual region and transfer safeguards will be published before production acceptance.